Back to Browse

Pkgproof MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.

About

Verify an npm package before you install it: advisories, install scripts, typosquats, provenance.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: 3 highly-trusted packages.

12 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

Base64 account key of a throwaway Algorand wallet holding USDC (ASA 31566704) on Algorand Mainnet. Not a 25-word mnemonic. Optional: the first verification each day is free without any key. This is the rail payments prefer.Required

Environment variable: PKGPROOF_ALGORAND_PRIVATE_KEY

0x-prefixed private key of a throwaway EVM wallet holding USDC on Base. Optional, and only used when no Algorand key is configured. Needs no ETH: payment is an off-chain signature and the facilitator pays the gas.Required

Environment variable: PKGPROOF_BASE_PRIVATE_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "net-pkgproof-pkgproof": {
      "env": {
        "PKGPROOF_BASE_PRIVATE_KEY": "your-pkgproof-base-private-key-here",
        "PKGPROOF_ALGORAND_PRIVATE_KEY": "your-pkgproof-algorand-private-key-here"
      },
      "args": [
        "-y",
        "@pkgproof/mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

pkgproof-mcp

An MCP server that verifies an npm package before you install it.

One tool, verify_package. It runs eight checks against pkgproof.net covering advisories, install scripts, typosquat and combosquat names, scope, repository provenance and maintainer reputation, and answers safe, caution, block or does_not_exist with every reason labelled as fact or heuristic against its source.

The first verification each day is free and needs no configuration at all. No account, no key, no signup. Later calls the same day cost $0.05 in USDC, paid per call over x402, and only if you configure a wallet.

Install

Nothing to install or host: your MCP client runs the server itself. Needs Node 22 or newer.

Every release from 0.1.1 on is built and signed by CI and carries an npm provenance attestation tying the tarball to the commit and workflow run that produced it. A tool that reports on other packages' provenance should be checkable the same way:

npm audit signatures

The server is also listed in the MCP Registry as net.pkgproof/pkgproof.

Free, no key

Add this to your MCP client configuration and you are done:

{
	"mcpServers": {
		"pkgproof": {
			"command": "npx",
			"args": ["-y", "@pkgproof/mcp"]
		}
	}
}

The tool

verify_package, and nothing else. One call is one verification, so the daily allowance means the same thing here as it does over HTTP.

ArgumentRequiredMeaning
nameyesPackage name, scoped or not: left-pad, @scope/thing.
versionnoExact version. Omit to verify the package rather than one release.
ecosystemnoDefaults to npm, the only ecosystem this service covers.

It answers twice over: a summary the agent reads, and the service's own JSON alongside it in structuredContent, under a declared output schema, carrying the verdict, every reason with its source, and the time the verdict was computed.

Calls run one at a time. The service allows one verification in flight per payer and refuses the second, so an agent walking a dependency list is queued here rather than failed.

Two networks

pkgproof settles on two chains, each on its own endpoint. They are not interchangeable: they take different key formats, and only one of them has a free tier.

Algorand MainnetBase
Endpointx402-algo.pkgproof.netx402.pkgproof.net
Networkalgorand:wGHE2Pwdvd7S12BL5FaOP20EGYesN73ktiC1qzkkit8=eip155:8453
AssetUSDC, ASA 31566704USDC, 0x8335…2913
Price$0.05 per verification$0.05 per verification
Free tierno, every call is paidyes, one verdict per caller per day
Key variablePKGPROOF_ALGORAND_PRIVATE_KEYPKGPROOF_BASE_PRIVATE_KEY
Key formatbase64 account key0x-prefixed EVM key
Network fee per paymentnone, sponsorednone, sponsored
One-time setup~0.3 ALGO, and an opt-in to the assetnone, just send USDC

How the server picks. The free attempt always goes to Base, because it is the only rail that answers an unpaid call. Payments prefer Algorand, and fall back to Base only when no Algorand key is configured. So a wallet on either chain works, and configuring neither still gets you a verdict a day.

Paid, with a wallet

[!WARNING] Fund a throwaway wallet, never a main one. The key is stored in plain text in your MCP client's configuration file, which is not an encrypted store, and anything able to read that file can spend the wallet. Put in what you are willing to spend on package verification and nothing more. There is deliberately no spend cap in this server, so the wallet's own balance is the only limit.

Algorand (preferred)

Verifications cost the account no ALGO. The 402 names a fee payer, so the facilitator covers the network fee on every payment and your ALGO balance does not move.

Setting the account up does cost ALGO, once. An Algorand account cannot receive an asset until it opts into it, so USDC sent to an account that has not opted in will not arrive. Three steps, in this order:

  1. Fund the throwaway account with about 0.3 ALGO. Algorand locks 0.1 as the account's minimum balance, another 0.1 for as long as it holds USDC, and the opt-in transaction itself costs a fee.
  2. Opt into ASA 31566704 (USDC on Mainnet). This is a zero-amount transfer from the account to itself; any Algorand wallet will do it.
  3. Send USDC to the account.

The key is the base64 account key, not a 25-word mnemonic.

{
	"mcpServers": {
		"pkgproof": {
			"command": "npx",
			"args": ["-y", "@pkgproof/mcp"],
			"env": {
				"PKGPROOF_ALGORAND_PRIVATE_KEY": "..."
			}
		}
	}
}

Base

Send USDC on Base to the throwaway wallet's address. You do not need ETH: payment is an off-chain signature and the facilitator pays the gas.

{
	"mcpServers": {
		"pkgproof": {
			"command": "npx",
			"args": ["-y", "@pkgproof/mcp"],
			"env": {
				"PKGPROOF_BASE_PRIVATE_KEY": "0x..."
			}
		}
	}
}

The server always tries the free call first, so a configured wallet is only charged once the day's free verification is used up.

Configuration

VariableRequiredMeaning
PKGPROOF_ALGORAND_PRIVATE_KEYnoThrowaway Algorand account holding USDC on Mainnet, base64. Preferred for payment when set.
PKGPROOF_BASE_PRIVATE_KEYnoThrowaway EVM wallet holding USDC on Base, 0x-prefixed. Used when no Algorand key is set.

With neither set, the server is free-tier only and says so once the day's verification is spent.

Development

npm install
npm test           # unit tests, and a real client handshake over an in-memory transport
npm run lint       # typecheck, formatting, eslint
npm run inspector  # build, then the MCP inspector against the local server

No test spends anything, and the suite enforces it rather than trusting it: a test that reaches for the network fails, and the run refuses to start at all if a wallet key is set in the environment. The payment path is exercised against a fabricated 402 and a published test account, so an EIP-3009 authorisation is signed locally and the payload and header are checked without a wallet.

Links

License

Apache-2.0. If you distribute a modified version, section 4(b) requires you to mark the files you changed: a fork of a security tool that still carries this name should not be mistakable for this one.

Reviews

No reviews yet

Be the first to review this server!